PT-2012-5454 · Openfabrics Alliance+2 · Librdmacm+2
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
librdmacm version 1.0.16
Description
The issue allows remote attackers to specify address resolution information for the application via a malicious ib acm service when ibacm.port is not specified, causing librdmacm to connect to port 6125.
Recommendations
For librdmacm version 1.0.16, consider specifying the
ibacm.port to avoid connecting to the default port 6125, which can be exploited by a malicious ib acm service. As a temporary workaround, restrict access to the ib acm service to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Librdmacm